CVE Published: 31/07/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: redhat |
Vendor: The Curl Project |
Product: curl Status : PUBLISHED
CVE-2016-8624 Description
curl before version 7.51.0 doesn\'t parse the authority component of the URL correctly when the host name part ends with a \'#\' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.